Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Tag

#Supply Chain

7 articles covering Supply Chain across campaign analysis, detection engineering, and defender tradecraft.

Coverage

7 entries

Field Analysis

Blue TeamTradecraft LabsJun 12, 202610 min read

The Recruiting Repo Is the Payload

A fake recruiter asking a candidate to review an MVP repo shows why unsolicited source code is not a document. It is an executable threat surface with access to developer secrets.

Read more:Reddit r/cybersecurityMicrosoft Security Blog

By PhishPond Desk

  • #Developer Security
  • #Fake Recruiters
  • #Supply Chain

Field Analysis

Blue TeamInfrastructure IntelligenceJun 7, 20268 min read

TrapDoor's Cross-Ecosystem Campaign Adds AI-Assistant Poisoning to Supply-Chain Tradecraft

Socket attributes a coordinated supply-chain campaign called TrapDoor to roughly thirty-four packages across npm, PyPI, and Crates.io, with ecosystem-specific execution paths and a new twist: planted .cursorrules and CLAUDE.md files designed to influence the developer's AI coding assistant.

Read more:SocketThe Hacker News

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Supply Chain
  • #Developer Security

Field Analysis

Dual UseCampaign AnalysisMay 31, 20266 min read

Ghost CMS ClickFix Wave Turns Trusted Sites Into Paste-and-Run Staging

A reported exploitation wave against Ghost CMS pushed malicious JavaScript onto more than 700 sites, sending visitors into fake verification flows that used ClickFix-style paste-and-run instructions.

Read more:The Hacker NewsMalwarebytes Labs

By PhishPond Desk

  • #Campaign Analysis
  • #ClickFix
  • #Web Compromise

Field Analysis

Blue TeamDetection & ValidationMay 31, 20266 min read

npm Staged Publishing Moves Package Security Toward Human-Gated Release

GitHub's staged publishing and new npm install-source controls give maintainers practical ways to slow compromised CI/CD paths before a malicious package becomes installable.

Read more:GitHub ChangelogCISA

By PhishPond Desk

  • #Detection & Validation
  • #Supply Chain
  • #Developer Security

Field Analysis

Dual UseTradecraft LabsMay 16, 202610 min read

APT Methods Watch: Geofenced Lures, ClickFix, and Supply Chain Trust

Recent actor reporting points to a practical trend line: adversaries are combining selective delivery, user-driven execution, and trusted developer channels.

Read more:The Hacker NewsDark Reading

By PhishPond Desk

  • #Tradecraft Labs
  • #Initial Access
  • #ClickFix

Field Analysis

Blue TeamDetection & ValidationMay 6, 20269 min read

The Drift Token Lesson Is SaaS Blast Radius, Not Just Vendor Risk

The Salesloft Drift incident showed how a trusted integration token can become an access path into customer SaaS data without a fresh user login.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #OAuth
  • #Supply Chain
  • #Salesforce

Field Analysis

Red TeamCampaign AnalysisApr 23, 202611 min read

Developer Tooling Compromise Turns Trusted Packages Into Phishing Surface

Recent package compromises show how developer trust can be abused to harvest credentials and seed downstream phishing risk.

Read more:BleepingComputerCISA

By PhishPond Desk

  • #Supply Chain
  • #Developer Security
  • #Credential Theft

Browse Other Tags

#Detection Engineering#OAuth#Credential Theft#Identity#AiTM#Campaign Analysis#Infrastructure Intelligence#MFA Bypass#SaaS Security#Tradecraft Labs#ClickFix#Developer Security